Minimal Rights and Permissions Required for InTrust Operations
Operation or Account | Permissions or Database Roles | Notes |
Run InTrust suite setup | Setup must be launched under the account that:
| When installing the second (and following) InTrust Servers into your InTrust Organization, check that the setup account is included into InTrust Organization Administrators (use the properties of InTrust Manager root node).
|
To install the reports from the Knowledge Packs you select, the following is required:
|
| |
To provide automatic creation of Service Connection Point (SCP) by InTrust means, you should perform the following before the setup:
Create a container"CN=Quest InTrust, CN=System..." and assign the following rights for this container for the account under which you will run the setup:
-OR- Specify the following permissions for the "CN=System..." in the Active Directory configuration partition for the account under which you will run the setup:
These permissions must be applied onto This object and all child objects scope. | ||
InTrust Server account |
| |
Install agent | Membership in the local Administrators group on the agent computer | The Admin$ share must exist on the target computer if you are installing the agent using InTrust. |
Agent account | Membership in the local Administrators group, -OR- LocalSystem account | |
Use the InTrust Manager snap-in | Membership in the AMS Readers computer local group on the InTrust Server | To view InTrust configuration objects in InTrust Manager, a user must be a member of the AMS Readers local group on the InTrust Server, or an InTrust organization administrator (included in the list in the properties of the root node in InTrust Manager). |
Access the configuration database | ADCCfgUser role for the configuration database | This role is created by setup or by the configdb.sql script and is granted the following permissions:
|
Gather events from site computers without agents |
| To gather events from an event log on a Windows Server 2003 or Windows XP computer with event log security through aGPO or registry settings, Read access permission must be given in the ACE of appropriate log(s) to the account used to run a job. For details refer to Microsoft KB article 323076. |
Gather events from site computers with agents | Full control permission to the InTrust Server installation folder. | To gather events from an event log on a Windows Server 2003 or Windows XP computer with event log security through aGPO or registry settings, Read access permission must be given in the ACE of the appropriate log(s) to the account of the agent. For details refer to Microsoft KB article 323076. |
Store events in a repository | Modify permission to the repository |
If a repository is accessed under the account specified explicitly (for repository, job or task account), membership in AMS Readers computer local group on the InTrust Server and Log on as a batch job right on the InTrust Server is required for that account.
|
Consolidate repositories |
| |
Import data from a repository |
| |
Clean up a repository | Modify permission to the repository | |
Store events in an audit database (gathering or import) | InTrust Gathering role for the Audit Database | This role is created by setup or by the auditdb.sql script. |
Clean up an audit database | To clean up all events db_owner role for the audit database | |
To clean up part of the events (for specific time periods) InTrust AuditDB Cleanup role for the audit database | This role is created by setup or by the auditdb.sql script. | |
Run reporting job or work with reports in Quest Knowledge Portal (without using Report Builder) |
|
Note that this account must belong to the same domain where SSRS (hosting Knowledge Portal) is installed, otherwise membership in the Authenticated Users group (for SRS' domain) is required. |
Add reports to a reporting job |
| |
Run reporting job using Import objects from the repository option | Rights and permissions required for both import and reporting jobs, sufficient rights for connection to the audit database. | For detailed list of rights and permissions required and security settings their usage depends on, refer to Report-driven Data Import section of the InTrust User Guide. |
Create reports interactively using Report Builder | System User or System Administrator role for the web site where the Knowledge Portal application runs. | This role can be assigned using SQL Reporting Services Report Manager (site-level security settings). |
Store alerts in an alert database | InTrust Real-Time Monitoring role for the alert database | This role is created by setup or by the alertdb.sql script. |
Clean up an alert database | InTrust AlertDB Cleanup role for the Alert Database | This role is created by setup or by the alertdb.sql script. |
Manage alerts from InTrust Monitoring Console | InTrust Monitoring Console role for the alert database | This role is created by setup or by the alertdb.sql script. |
Create and edit a profile in Monitoring Console | Administrator role for COM+ System Application on the computer where the Monitoring Console runs. | To check if you have this role, open the Component Services MMC snap-in on the computer with Monitoring Console, and view the Computers | My Computer | COM+ Applications | System Application | Roles | Administrator | Users node. |
Connect to an alert database using SQL Server authentication | For a profile to use SQL Server authentication when connecting to the alert database, the Run As account should be included into local Administrators group on the computer where the Monitoring Console is installed. | |
Perform indexing of idle repository with standalone IndexingTool.exe | Both on the repository folder and on the index folder, for the account that perform indexing:
| |
Perform indexing of a production repository |
| |
Open an idle repository in Repository Viewer | Both on the repository folder and on the index folder, for the account used to open Repository Viewer:
| |
Open a production repository in Repository Viewer |
|
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center